Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Summary
Fortinet has released patches for critical vulnerabilities affecting its FortiMonitorOnSight product and a Chrome extension. These unauthenticated bugs allow attackers to bypass authentication and proxy user browser traffic.
IFF Assessment
The discovery and exploitation of critical vulnerabilities that allow for authentication bypass and traffic proxying represent a significant threat to organizations using the affected Fortinet products.
Severity
The vulnerabilities allow for authentication bypass and proxying of user traffic without authentication, indicating a high attack complexity and significant impact on confidentiality and integrity.
Defender Context
Defenders should prioritize patching these critical vulnerabilities in Fortinet's FortiMonitorOnSight and associated Chrome extensions immediately. Unpatched systems are at high risk of unauthorized access and traffic manipulation, potentially leading to further compromise.